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- The MAILING DATE of this communication appears on the cover sheet with the correspondence address ■ 
Period for Reply 

A SHORTENED STATUTORY PERIOD FOR REPLY IS SET TO EXPIRE 3 MONTH(S) FROM 
THE MAILING DATE OF THIS COMMUNICATION. 

- Extensions of time may be available under the provisions of 37 CFR 1 . 1 36(a). In no event, however, may a reply be timely filed 
after SIX (6) MONTHS from the mailing date of this communication. 

- If the period for reply specified above is less than thirty (30) days, a reply within the statutory minimum of thirty (30) days will be considered timely. 

- If NO period for reply is specified above, the maximum statutory period will apply and will expire SIX (6) MONTHS from the mailing date of this communication. 

- Failure to reply within the set or extended period for reply will, by statute, cause the application to become ABANDONED (35 U.S.C. § 1 33). 
Any reply received by the Office later than three months after the mailing date of this communication, even if timely filed, may reduce any 
earned patent term adjustment. See 37 CFR 1.704(b). 

Status 

1 )^ Responsive to communication(s) filed on 22 April 2004 . 
2a)D This action is FINAL. 2b)^ This action is non-final. 

3) D Since this application is in condition for allowance except for formal matters, prosecution as to the merits is 

closed in accordance with the practice under Ex parte Quayle, 1935 CD. 11, 453 O.G. 213. 

Disposition of Claims 

4) ^ Claim(s) 1-7.10-16 and 19-25 is/are pending in the application. 

4a) Of the above claim(s) is/are withdrawn from consideration. 

5) D Claim(s) is/are allowed. 

6) ^ Claim(s) 1-7,10-16 and 19-25 is/are rejected. 

7) D Claim(s) is/are objected to. 

8) Q Claim(s) are subject to restriction and/or election requirement. 

Application Papers 

9) D The specification is objected to by the Examiner. 

10) D The drawing(s) filed on is/are: a)D accepted or b)Q objected to by the Examiner. 

Applicant may not request that any objection to the drawing(s) be held in abeyance. See 37 CFR 1.85(a). 
Replacement drawing sheet(s) including the correction is required if the drawing(s) is objected to. See 37 CFR 1.121(d). 

1 1) D The oath or declaration is objected to by the Examiner. Note the attached Office Action or form PTO-152. 

Priority under 35 U.S.C. § 119 

12) D Acknowledgment is made of a claim for foreign priority under 35 U.S.C. § 1 19(a)-(d) or (f). 
a)D All b)D Some * c)D None of: 

1 .□ Certified copies of the priority documents have been received. 

2.Q Certified copies of the priority documents have been received in Application No. . 



3.Q Copies of the certified copies of the priority documents have been received in this National Stage 
application from the International Bureau (PCT Rule 17.2(a)). 
* See the attached detailed Office action for a list of the certified copies not received. 
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DETAILED ACTION 



Claim Rejections - 35 USC §112 

1 . The following is a quotation of the first paragraph of 35 U.S.C. 1 12: 

The specification shall contain a written description of the invention, and of the manner and 
process of making and using it, in such full, clear, concise, and exact terms as to enable any 
person skilled in the art to which it pertains, or with which it is most nearly connected, to make 
and use the same and shall set forth the best mode contemplated by the inventor of carrying 
out his invention. 

2. Claims 1-7,10-16, and 19-25 are rejected under 35 U.S.C. 112, first 
paragraph, as failing to comply with the enablement requirement. The claim(s) 
contains subject matter which was not described in the specification in such a 
way as to enable one skilled in the art to which it pertains, or with which it is most 
nearly connected, to make and/or use the invention. 

The applicant has amended the claims 1,10, and 19 to recite of "wherein 
only applications associated with the given application client and not applications 
associated with other clients will receive the security context for the given client" 
and the examiner can not find support in the applicant's specification for this 
recently added claim limitation. Being a negative limitation, it is not sufficiently 
disclosed in a adequate manner in the applicant's specification to support the 
current claim language. 




" Application/Control Number: 09/577,220 Page 3 

Art Unit: 2131 

Claim Rejections - 35 USC § 103 

3. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for 
all obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described 
as set forth in section 1 02 of this title, if the differences between the subject matter sought to 
be patented and the prior art are such that the subject matter as a whole would have been 
obvious at the time the invention was made to a person having ordinary skill in the art to which 
said subject matter pertains. Patentability shall not be negatived by the manner in which the 
invention was made. 

4. Claims 1-6,10-15, and 19-24 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Gongwer et al in view of Alegre et al in further view of Hoang 
et al. 

In regards to claims 1,10 and 19, Gongwer teaches a system for sharing 
a security context between different applications on a database server 
associated with a given application client (col. 1, lines 58-61), comprising: 

receiving a request at the database server through a database session 
between the database server and an application on a database client (i.e. an 
originating application (client) connects to a data server and creates a session, 
specifying that the session be brand new, and that the new session can be 
shared by future client connections) (col. 1, lines 44-47); 

looking up an identifier for a given application client that identifies a client 
of the application, the identifier having been previously associated with the 
database session (i.e. the server recognizes the clients by assigning a respective 
identifier, called a session handle, to each client) (col. 2, lines 1-4); 
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using the identifier to look up the security context (i.e. exclusive security 
data) for the application client within a storage area (i.e. Securityspace) 
associated with the database server (col. 4, lines 59-62); and 
wherein the security context includes attributes related to the given application 
client (i.e. additional information which can be used, for example, by the security 
manager to authenticate clients) (col.12, lines 33-35); and 

allowing the application client to use the same security context through a 
second application and a second database session (i.e. sessHandle 2 ) by: 

receiving a second request at the database server through the second 
database session with the second application (i.e. passing the received 
workspace handle (wsHandlei) to the session manager as part of its session 
initialization procedure); 

looking up the identifier for the application client, the identifier having been 
previously associated with the second database session; and 

using the identifier to look up the security context for the given application 
client within the storage area associated with the database server (i.e. updating 
the mapping table for this session's entry to reference the Workspace of the 
originating client) (col.12, lines 47-65). 

Gongwer does not teach: 

receiving the security context for the given application client from the 
database client; 
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inserting the security context into the storage area associated with the 
database server so that the security context can be indexed by the identifier for 
the application client; and 

performing a database operation to satisfy the request; 
wherein performing the database operation involves enforcing access rights 
associated with the security context. 

Alegre teaches: 

receiving the security context for the given application client from the 
database client (i.e. authentication server first receives the UID and PWD from 
login process as part of the initial login by the user at client browser) (col. 6, lines 
24-27); 

inserting the security context into the storage area associated with the 
database server so that the security context can be indexed by the identifier for 
the given application client (i.e. authentication database stores information 
defining which users may access resources on trusted network. Authentication 
database also stores user profile information that defines the types of access 
each user has to the resources on trusted network.) (col. 6, lines 29-33). 

performing a database operation to satisfy the request (i.e. if the session 
key is still valid, access server performs the request) (col. 4, lines 63-63); 
wherein performing the database operation involves enforcing access rights 
associated with the security context (i.e. authentication database also stores user 
profile information that defines the types of access each user has to the 
resources on trusted network) (col. 6, lines 29-31). 
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Therefore it would have been obvious to one of ordinary skill in the art at 
the time of Applicant's invention to modify the teaching of Gongwer with the 
teachings of Alegre to include receiving the security context for the given 
application client from the database client; inserting the security context into the 
storage area associated with the database server so that the security context can 
be indexed by the identifier for the given application client; and performing a 
database operation to satisfy the request; wherein performing the database 
operation involves enforcing access rights associated with the security context 
with the motivation to achieve a higher level of security for a trusted network in 
order to allow access by users on the Internet in a controlled and secure manner 
(Alegre, col. 2, lines 33-35). 

The combination of Gongwer and Alegre do not teach: 

Only applications associated with the given application client and not 
applications associated with other clients will receive the security context for the 
given client. 

Hoang teaches: 

A given application client receive a cookie (security context) that includes 
a unique identification code when a user client (given application client) goes to a 
local commerce site (which includes applications)(col. 3, lines 30-40). It is 
interpreted by the examiner that the cookie is associated to that particular client 
and not associated with other clients since it includes a unique identification 
code. 
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It would have been obvious to a person of ordinary skill in the art at the 
time of the invention to have been motivated to apply the use of applying security 
context that is particular to a client and not other clients. The teachings of Hoang 
recites motivation for the use of applying security context that is particular to a 
client and not other clients by disclosing that servers typically do not keep track 
of client requests for web pages (applications), but can send identification code 
back to the clients whereby the client maintains this specific information (col. 1 , 
lines 49-67). The combination of the teachings of Gongwer and Alegre would 
have been simplified wherein the same client making multiple request would 
have been recognized by its unique identification code that is associated with a 
cookie as is disclosed by Hoang. 

In regards to claims 2, 11 and 20, Gongwer teaches wherein the request 
includes a database query (i.e. transaction) directed to a database (figure 1 , 
element 5) on the database server (figure 1 , element 10). The Office infers that 
conducting a transaction with a database server comprises directing a query to 
the database. 

In regards to claim 3, 12 and 21 , Gongwer does not teach wherein 
performing the database operation involves modifying the database query to 
enforce access rights associated with the security context. 

Alegre teaches wherein performing the database operation involves 
modifying the database query to enforce access rights associated with the 
security context (i.e. the trusted network access presentation information is 
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created based on the user access profile, and thus includes only selection for 
accessing resources that the user has access to) (col. 4, lines 44-47). 
Therefore it would have been obvious to one of ordinary skill in the art at the time 
of Applicant's invention to modify the teaching of Gongwer with the teachings of 
Alegre to include wherein performing the database operation involves modifying 
the database query to enforce access rights associated with the security context 
with the motivation to achieve a higher level of security for a trusted network in 
order to allow access by users on the Internet in a controlled and secure manner 
(Alegre, col. 2, lines 33-35). 

In regards to claim 4, 13 and 22, Gongwer does not teach wherein the 
identifier for the application client identifies a user of the application that is 
sending the request to the database server. 

Alegre teaches wherein the identifier for the application client identifies a 
user of the application (i.e. user ID [UID]) that is sending the request to the 
database server (col. 4, lines 24-26). 

Therefore it would have been obvious to one of ordinary skill in the art at 
the time of Applicant's invention to modify the teaching of Gongwer with the 
teachings of Alegre to include wherein the identifier for the application client 
identifies a user of the application that is sending the request to the database 
server with the motivation to achieve a higher level of security for a trusted 
network in order to allow access by users on the Internet in a controlled and 
secure manner (Alegre, col. 2, lines 33-35). 
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In regards to claim 5, 14 and 23, Gongwer teaches wherein the database 
client is an application server that is sending the request to the database server 
(i.e. the clients are preferably application programs. The application programs 
can be executing on common computer or on distinct computers) (col. 2, lines 
32-34). 

Gongwer does not teach wherein the identifier for the application client 
identifies an application session between the application on the application 
server and the client of the application. 

Alegre teaches wherein the identifier for the application client identifies an 
application session between the application on the application server and the 
client of the application (i.e. the packet may be created by merely concatenating 
a web server identifier, speaker object identifier, or other identifier, to the session 
key and URL request received from the user). The Office infers that "other 
identifier" includes the use of an identifier of the application session between the 
application on the application server and the client of the application. 

Therefore it would have been obvious to one of ordinary skill in the art at 
the time of Applicant's invention to modify the teaching of Gongwer with the 
teachings of Alegre to include wherein the identifier for the application client 
identifies an application session between the application on the application 
server and the client of the application with the motivation to achieve a higher 
level of security for a trusted network in order to allow access by users on the 
Internet in a controlled and secure manner (Alegre, col. 2, lines 33-35). 
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In regards to claim 6, 15 and 24, Gongwer teaches receiving a request 
from the application to change the application session associated with the 
database session; and changing the application session associated with the 
database session (i.e. applications can create, and actively share a session) (col. 
11, lines 64-65). 

5. Claims 7,16, and 25 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Gongwer et al in view of Alegre et al in further view of Hoang 
et al in further view of Chatterjee et al. 

The teachings of Gongwer, Alegre, and Hoang have been discussed 

above. 

The combination of Gongwer, Alegre, and Hoang, however, does not 
teach further comprising facilitating connection pooling by periodically changing 
the application session associated with the database session in order to channel 
requests associated with multiple application sessions through the database 
session. 

Chatterjee teaches further comprising facilitating connection pooling by 
periodically changing (i.e. switching) the application session associated with the 
database session in order to channel requests associated with multiple 
application sessions through the database session (col. 3, lines 39-55). 
Therefore it would have been obvious to one of ordinary skill in the art at the time 
of Applicant's invention to modify the teaching of Gongwer, Alegre, and Hoang 
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with the teachings of Chatterjee to include further comprising facilitating 
connection pooling by periodically changing the application session associated 
with the database session in order to channel requests associated with multiple 
application sessions through the database session with the motivation to allow 
more users to use a server than the number of connections established with the 
server (Chatterjee, col. 3, lines 25-27). 

Conclusion 

6. Any inquiry concerning this communication or earlier communications from 
the examiner should be directed to Christopher A. Revak whose telephone 
number is 703-305-1843. The examiner can normally be reached on Monday- 
Friday, 6:30am-4:00pm. 

If attempts to reach the examiner by telephone are unsuccessful, the 
examiner's supervisor, Ayaz Sheikh can be reached on 703-305-9648. The fax 
phone number for the organization where this application or proceeding is 
assigned is 703-872-9306. 
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Information regarding the status of an application may be obtained from 
the Patent Application Information Retrieval (PAIR) system. Status information 
for published applications may be obtained from either Private PAIR or Public 
PAIR. Status information for unpublished applications is available through 
Private PAIR only. For more information about the PAIR system, see http://pair- 
direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll- 
free). 




Christopher Revak 
AU2131 ; 



July 23, 2004 



